Method for detecting hidden trailing jamming attack based on geometric consistency and constraint screening
By filtering out the set of attack states that meet the conditions of physical feasibility and business damage in the mobile edge computing system, and constructing a robust log-likelihood ratio increment for sequential accumulation, the problem of difficulty in identifying reactive pilot-tail interference in the existing technology is solved, and effective detection and reliable defense in dynamic scenarios are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIDIAN UNIV
- Filing Date
- 2026-05-29
- Publication Date
- 2026-07-28
AI Technical Summary
Existing technologies struggle to effectively identify and defend against reactive pilot-tail interference attacks in mobile edge computing systems, especially in dynamic scenarios where it is difficult to distinguish between normal geometric drift and malicious interference offsets, resulting in high false alarm and false negative rates. Furthermore, existing methods are unable to provide reliable security guarantees.
By acquiring the received signals of legitimate drones, calculating the logarithmic power statistics of time slots and generating detection residuals by combining them with map anchoring residuals, a set of attack states that meet the conditions of physical feasibility and business damage is selected, a robust log-likelihood ratio increment is constructed and sequentially accumulated, and it is determined whether the control link is subjected to tailing interference.
It effectively reduces the interference of geometric drift on the detection results, maintains good detection stability and separation capability, can identify long-term tailing and gradual injection of hidden interference, and provides robustness and worst-case reliability guarantees in dynamic scenarios.
Smart Images

Figure CN122476348A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of control link security technology for mobile edge computing systems, specifically involving a method for detecting covert tailing interference attacks based on geometric consistency and constraint screening. Background Technology
[0002] In mobile edge computing systems, base stations control and schedule resources for legitimate UAVs via downlink control beacons and task offloading pilots to ensure low-latency, continuous control plane services (W. Lu et al., Secure NOMA-Based UAV-MEC Network Towards a Flying Eavesdropper, IEEE Transactions on Communications, vol. 70, no. 5, pp. 3364-3376, May 2022; Z. Han, T. Zhou, T. Xu and H. Hu, Joint User Association and Deployment Optimization for Delay-Minimized UAV-Aided MEC Networks, IEEE Wireless Communications Letters, vol.12, no. 10, pp. 1791-1795, Oct. 2023). However, aerial attackers can exploit the openness of wireless links and the observability of control cues to launch reactive pilot-tailing covert jamming attacks. Attackers continuously track and closely follow the flight paths of legitimate drones, opportunistically injecting jamming power during critical time slots. This causes deterioration in control signal reception quality, reduced throughput of offloaded links, and service interruptions, further inducing queuing accumulation and latency default risks in the mobile edge computing control plane. This type of tailing jamming attack is not a blind high-power suppression, but rather a covert disguise achieved by combining geometric position and propagation patterns. The received power shift caused by the jamming can often be masked by legitimate geometric changes, making it difficult for traditional anomaly detection methods based on single-slot energy thresholds or fixed baselines to distinguish between normal geometric drift and malicious jamming shifts. Furthermore, both attackers and legitimate drones are subject to kinematic constraints such as no-fly zones and maximum speeds; the attack location and power selection must fall within the physically feasible domain. However, existing detection and modeling methods often ignore these strong prior constraints, resulting in an excessively large attack hypothesis space and making it difficult to simultaneously control false positives and false negatives in the worst-case scenario.
[0003] Existing intelligent interference or anomaly detection technologies for UAV-assisted mobile edge computing control links mainly fall into three categories: The first category is based on received power thresholds or other statistical anomalies. This type of method monitors time-slot-level received power, signal-to-noise ratio (SNR), or signal-to-interference-plus-noise ratio (SINR) or their statistics, sets static or dynamic thresholds, and determines the presence of interference or link anomalies when observed values exceed preset normal ranges. Its core assumption is that interference will cause a significant shift in energy or statistical distribution, thus allowing direct identification through threshold exceedances.
[0004] The second category is based on detecting anomalies in time-series changes or state evolution. This type of method focuses on the evolution of reception quality over time or link changes caused by flight status. It uses filtering, prediction models, or learning models to establish normal evolution patterns, triggering an alarm when the observed sequence deviates continuously or abruptly from the predicted trajectory. Its core assumption is that attacks cannot accurately disguise themselves as a continuous process conforming to system dynamics and service evolution over a long period.
[0005] The third category comprises detection schemes based on machine learning or data-driven classification (W. Lu et al., SecureNOMA-Based UAV-MEC Network Towards a Flying Eavesdropper, IEEE Transactions on Communications, vol. 70, no. 5, pp. 3364-3376, May 2022; B. Rao, J. Hu, A. Al-Nahari, K. Yang and R. Jantti, On the Physical Layer Security of UAV-AidedBackscatter Communications, IEEE Wireless Communications Letters, vol. 13, no. 2, pp. 274-278, Feb. 2024). These methods typically extract features from received signals, link quality indicators, or multi-dimensional environmental observations, and utilize supervised learning, deep learning, or other trained classification models to identify interference or anomalies in the current state. Their core assumption is that the sample distribution obtained during training can effectively cover the actual operating environment, and that the model can maintain its generalization ability to new scenarios and new attack behaviors after deployment. The above-mentioned scheme is also supported by the technical specifications for physical layer procedures developed by the 3GPP (3GPP, NR; Physicallayer procedures for data, 3GPP TS 38.214, Version 19.1.0, 3GPP, 2025).
[0006] However, existing technical solutions have the following drawbacks: The first type of scheme, based on received power thresholds or other statistical anomalies, lacks sufficient ability to identify covert tailing interference. During continuous UAV maneuvers, received power naturally fluctuates with changes in flight position, link distance, path loss, and shadow fading. Attackers can exploit this geometric drift and channel fluctuations as cover, opportunistically adjusting the timing of interference injection and transmit power to mask the resulting energy rise within normal fluctuation ranges. This means that although the received energy has been maliciously affected, it may not exhibit significant out-of-bounds characteristics within a single time slot. Furthermore, the harm of tailing interference often manifests as a continuous accumulation of weak offsets over multiple time slots rather than a one-time strong abrupt change. Therefore, this type of method is insensitive to persistent, gradual, and highly camouflaged interference behaviors, making it difficult to simultaneously achieve low false alarms and high detection rates.
[0007] The second type of scheme, based on the detection of time-series changes or state evolution anomalies, is insufficiently adaptable to smooth camouflage attacks. Reactive pilot-tail jamming attacks are not random and brute-force interference, but rather continuously track the geometric position and movement trends of legitimate UAVs. Under kinematic constraints such as maximum speed, they smoothly adjust their own position and interference intensity, ensuring that the statistical changes observed at the receiver remain continuous in time, and are disguised as natural evolution caused by normal flight, obstruction, or channel changes. Meanwhile, task scheduling, resource allocation, and link load in mobile edge computing systems themselves can cause non-stationary changes in service statistics, making normal sequence models prone to drift. This makes it difficult to reliably distinguish between smooth shifts caused by real attacks and natural fluctuations caused by the system's own evolution, easily leading to increased false alarms or decreased detection rates in dynamic scenarios.
[0008] The third type of scheme, based on machine learning or data-driven classification, is not adaptable to environmental drift and cannot provide worst-case reliability guarantees. In UAV-assisted mobile edge computing scenarios, the link geometry and reception statistics continuously change with the UAV's position, attitude, propagation environment, and task scheduling status, which can easily lead to a distribution mismatch between training data and actual operational data (W. Lu et al., Secure NOMA-Based UAV-MEC Network Towards a Flying Eavesdropper, IEEE Transactions on Communications, vol. 70, no. 5, pp.3364-3376, May 2022; Z. Han, T. Zhou, T. Xu and H. Hu, Joint User Association and Deployment Optimization for Delay-Minimized UAV-Aided MEC Networks, IEEE Wireless Communications Letters, vol. 12, no. 10, pp. 1791-1795, Oct. 2023). For reactive navigation and tailing covert jamming attacks, such solutions usually require frequent retraining or recalibration, and are mostly one-off decisions. They are difficult to uniformly incorporate physical constraints and business damage conditions, and it is also difficult to provide reliability guarantees for the worst-case scenario.
[0009] Therefore, the aforementioned deficiencies make it difficult for existing technologies to provide reliable, explainable, and authenticable security guarantees for mobile edge computing control links under controllable false alarm conditions. Summary of the Invention
[0010] To address the aforementioned problems in the existing technology, this application provides a method for detecting covert tailing interference attacks based on geometric consistency and constraint screening. The technical problem to be solved by this application is achieved through the following technical solution: A method for detecting covert tailing interference attacks based on geometric consistency and constraint screening includes: S1, acquire the received signals of legal UAVs in each time slot, calculate the logarithmic power statistics of the time slot based on the received signals, and generate detection residuals by combining the map anchoring residuals; S2, from the pre-built set of attack states, select a set of feasible and business-damaging attack states that meet the physical feasibility conditions and the business damage conditions, and determine the minimum authentication offset on the set of feasible and business-damaging attack states. S3, construct the robust log-likelihood ratio increment for each time slot based on the detection residual and the authentication minimum offset; S4, based on the robust log-likelihood ratio increment, perform sequential accumulation to obtain the sequential accumulation statistic; S5, compare the sequential cumulative statistics with a preset detection threshold, and determine that the control link is subjected to tailing interference when the sequential cumulative statistics exceed the detection threshold.
[0011] Beneficial effects: First, compared to schemes based on received power thresholds or other statistical anomalies, this application does not directly determine whether the time slot-level received power exceeds the limit. Instead, it first uses map anchoring residuals to remove the deterministic effects caused by legitimate flight geometry changes, path loss changes, and background fluctuations. Then, it combines the attack feasible region and service impairment conditions to extract the authenticable offset. Therefore, this application can effectively reduce the interference of geometric drift on the detection results, prevent attackers from bypassing simple threshold detection through fine power adjustment or geometric camouflage, and maintain good detection stability and separation capability even under weak interference conditions.
[0012] Second, compared with schemes based on time series changes or state evolution anomaly detection, this application does not rely on the prediction error of the link state evolution trajectory to trigger alarms. Instead, it uses worst-case authentication and robust log-likelihood ratio increment for sequential cumulative decision-making. Therefore, it can identify long-term tailing, gradual injection and hidden interference with smooth camouflage characteristics, and avoid the problem of increased false alarms or decreased detection rate in dynamic scenarios.
[0013] Third, compared with machine learning-based or data-driven classification schemes, this application does not rely on the training samples fully covering the real environment, nor on the model's stable generalization ability in dynamic scenarios. Instead, it explicitly incorporates no-fly zone constraints, kinematic reachability constraints, and service impairment conditions into the detection process. Therefore, it can maintain strong robustness under dynamic airspace and non-stationary service conditions and provide reliability guarantees for worst-case scenarios. Simulation results show that the proposed method can obtain a larger worst-case signal offset margin after constraint screening, and maintains the maximum authentication isolation distance under different interference intensities and no-fly zone radii.
[0014] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0015] Figure 1 This is a flowchart illustrating a method for detecting covert tailing interference attacks based on geometric consistency and constraint screening provided in this application. Figure 2 This is a schematic diagram of the UAV-assisted mobile edge computing system model provided in this application; Figure 3 This is a schematic diagram comparing the certifiable constraint screening sequential detection method of this application with existing methods in terms of worst-case signal offset margin; Figure 4 This is a comparison chart of the certification isolation distance of this application and existing methods under different interference signal ratios and no-fly zone radii. Detailed Implementation
[0016] The present application will be described in further detail below with reference to specific embodiments, but the implementation of the present application is not limited thereto.
[0017] like Figure 1 As shown, this application provides a method for detecting covert tailing interference attacks based on geometric consistency and constraint screening, including: S1, acquire the received signals of legal UAVs in each time slot, calculate the logarithmic power statistics of the time slot based on the received signals, and generate detection residuals by combining the map anchoring residuals; refer to Figure 2 In a UAV-assisted mobile edge computing system, the base station schedules and controls authorized UAVs via downlink control beacons and task offloading navigation. Because authorized UAVs exhibit significant maneuverability during flight, and because air-to-ground propagation links are sensitive to three-dimensional geometry, the received power experiences time-varying drift depending on the UAV's position, link distance, and path loss. Therefore, let the base station's position vector be... , No. Legitimate drones in time slots The position vector is The geometric distance between the two is Within each time slot, legitimate drones collect data. A quick snapshot of a complex base band The time-slot logarithmic power statistic S[n] is calculated. Simultaneously, based on the coverage map or a large-scale path loss model, the benign reference receiver logarithmic power under the same geometric state is calculated. . This characterizes the expected reception level determined by the three-dimensional geometry of a legitimate link when unaffected by attacks. Further, this is achieved by calculating the detection residuals. By stripping away the deterministic background drift caused by legitimate geometric changes, stable observations can be obtained for subsequent interference detection.
[0018] S2, from the pre-built set of attack states, select a set of feasible and business-damaging attack states that meet the physical feasibility conditions and the business damage conditions, and determine the minimum authentication offset on the set of feasible and business-damaging attack states. This application constructs an attack state space that includes attacker location, transmission power, kinematic reachability, no-fly zone constraints, and service impairment conditions. From this space, it filters out a set of feasible and service-impairing attack states that satisfy both physical reachability and genuinely impact legitimate control links. Furthermore, it extracts the least unfavorable but necessarily true minimum mean offset from this set, forming the authentication lower bound for tailing interference.
[0019] S3, construct the robust log-likelihood ratio increment for each time slot based on the detection residual and the authentication minimum offset; S4, based on the robust log-likelihood ratio increment, perform sequential accumulation to obtain the sequential accumulation statistic; S5, compare the sequential cumulative statistics with a preset detection threshold, and determine that the control link is subjected to tailing interference when the sequential cumulative statistics exceed the detection threshold.
[0020] The robust log-likelihood ratio increment for each time slot is constructed based on the detection residual and the minimum authentication offset. This increment exhibits a negative drift under normal conditions and a positive drift when a trailing disturbance meeting the service impairment condition is present. Sequential accumulation is performed based on the robust log-likelihood ratio increment to obtain the sequential accumulation statistic. The recursive form is: ,in The statistic falls back promptly under normal conditions, but rises steadily under continuous tailing interference. Finally, when the sequential cumulative statistic first exceeds the detection threshold η, it is determined that the control link has been subjected to tailing interference, and an alarm is output. The detection stop time is defined as: .
[0021] In one specific embodiment of this application, S1 includes: S11, obtain the position vector of the base station and the position vector of the legal UAV in each time slot, and calculate the geometric distance between them; Specifically, let the location vector of the base station be... The position vector of the k-th legitimate UAV in time slot n is The geometric distance between the two is .
[0022] S12, Calculate the benign reference receiver log power based on the coverage map or large-scale path loss model and the geometric distance; S13: Collect multiple complex baseband snapshots within the received signals of legal UAVs in each time slot, and calculate the logarithmic power statistics of the time slot; Within each time slot, legitimate drones collect data. A quick snapshot of a complex base band And calculate the time slot logarithmic power statistic S[n].
[0023] S14, subtract the benign reference reception logarithmic power from the time slot logarithmic power statistic to obtain the detection residual.
[0024] Based on the coverage map or large-scale path loss model, calculate the benign reference receiver log power under the same geometric state. . This characterizes the expected reception level determined by the three-dimensional geometry of a legitimate link when unaffected by attacks. Further, this is achieved by calculating the detection residuals. By stripping away the deterministic background drift caused by legitimate geometric changes, stable observations can be obtained for subsequent interference detection.
[0025] In one specific embodiment of this application, S2 includes: S21. Based on the kinematic reachability constraints and no-fly zone avoidance constraints of the attack drone, determine the reachable location area of the attack drone in each time slot, and construct an attack state set in combination with the transmission power range; wherein, the attack state set includes the position of the attack drone, transmission power, kinematic reachability constraints, no-fly zone constraints, and service damage conditions; Attack drones By passively observing the control cues of the legitimate formation and the geometry of the lead drone, a reactive tailing jamming is initiated. The attacker first determines the index of the lead drone. and time slots The position of the last pilot drone is recorded as To avoid tracking loss and latency mismatch caused by simple tracking, attackers use predictive tracking guidance laws to construct tail tracking vectors. Integrating instantaneous position difference with motion trend prediction: ; in, To attack drones in time slots The last position, The speed of the lead drone as observed by the attacker from the previous time slot. For predicting gain factors, This is the time slot length. Subsequently, the attackers traveled at maximum speed. Align your own speed to Direction, thereby achieving continuous tailing and approximation. , Under this tail-random movement, the attacker further uses an effective interference radius. Describe the geometric triggering conditions for the interference to take effect: Interference is considered to cause business disruption only if an attacker enters the critical area of the pilot drone: .in The receiver's tolerance threshold for interference signal-to-noise ratio is mapped to a geometric boundary to calibrate deterministic link failure zones.
[0026] In terms of signal generation and propagation modeling, attackers in time slots With transmission power Sending tailing interference signals to legitimate drones The air-to-air link gain is described using a fading model as follows: ; in and These are the reference gain and path loss exponent for the air-to-air link, respectively. Rician factor, , This is the scattering component.
[0027] For any time slot The hypothetical attack state, with an interference-to-noise ratio threshold. Define the service loss criteria: ; in, For the air-to-ground link gain from the base station to the legal drone, The base station transmit power is used as the criterion. This criterion effectively describes the conditions for generating an attack signal that follows into the effective interference zone and injects sufficient power to interfere with the signal.
[0028] Attack drones on the system's operating carrier frequency With bandwidth Simultaneous tailing interference injection at the same frequency and band is implemented on the control link: Attackers use passive eavesdropping / energy sensing to capture time slot boundaries and transmission activity in the BS control link, thereby interfering with transmission windows and time slots. Legitimate control transmission alignment ensures that interfering signals are within the bandwidth. The internal and legitimate control signals are superimposed at the receiving end. (In the time slot) Inside, legal drones In working bandwidth Upload Each complex baseband sample Its received signal model is written as: ; in and These represent the transmission power of the BS and the attacker, respectively. and These are the air-to-ground and air-to-air link gains, respectively. and For unit energy baseband symbol, satisfying Additive noise is bandwidth-limited complex white Gaussian noise. And can be determined by noise power spectral density With system bandwidth Represented as Within a time slot, and Approximately quasi-static invariance. Based on the aforementioned trailing interference motion law and signal injection method, in the time slot... A unified model is constructed to determine the possible locations and transmission power of attackers, thereby creating a set of attack states. .
[0029] S22, Select physically feasible attack states that satisfy kinematic reachability constraints and no-fly zone avoidance constraints from the set of attack states; S23, filter out the service-damaging attack states that satisfy the interference-to-noise ratio threshold from the physically feasible attack states to obtain a set of feasible and service-damaging attack states. Considering that an attacking drone must simultaneously satisfy kinematic reachability, no-fly zone avoidance, and transmit power range constraints, its attack state set can be represented as follows: ,in, This indicates that the attacker is in the time slot. The reachable location area and This indicates the range of transmit power allowed for the attacker. Furthermore, combining this with the service impairment criterion from step 3, the attack state set... The attack states that can cause actual business impact on the control link are selected from the data to obtain a set of feasible and business-damaging attack states: ; in, This indicates that the attacker is located at location [location missing]. Time to legalize drones Channel gain, Indicates the connection between the base station and the legitimate drone. The control link channel gain. The above set In essence, it represents all attack states that are physically reachable and can actually cause service disruption.
[0030] S24, on the set of feasible and business-damaging attack states, calculate the mean offset introduced by each attack state on the detection residual, and take the minimum value of the mean offset as the minimum authentication offset.
[0031] Because the detector cannot know in advance where the attacker is located in the set This application does not perform hypothesis testing for a specific fixed attack state, but rather on a set of precise locations and precise transmission powers. A unified worst-case authentication is performed. Let the mean shift introduced by the attack state on the detection residual be... Then in the set Take the minimum value above, and define the minimum authentication offset as: ; The above definition indicates that this step does not rely on the attacker's precise state parameters, but rather extracts the smallest offset from all valid attack states that is most unfavorable to the detector but necessarily valid for the attack as the authentication metric. In other words, as long as the attack truly exists and belongs to... Therefore, the mean shift caused by the received residual must be no less than .
[0032] In one specific embodiment of this application, S3 includes: Based on the detection residual, the minimum authentication offset, and the variance of the detection residual, construct the robust log-likelihood ratio increment for each time slot; the robust log-likelihood ratio increment is the minimum authentication offset divided by the variance of the detection residual multiplied by the detection residual, and then subtracted by the square of the minimum authentication offset divided by twice the variance of the detection residual.
[0033] Wherein, the detection residual follows a zero-mean Gaussian distribution when there is no attack; when there is a real attack and the attack state corresponding to the real attack belongs to the set of feasible and business-damaging attack states, the detection residual follows a Gaussian distribution with a mean not less than the minimum authentication offset.
[0034] When the set of feasible and business-damaging attack states is not empty, the minimum authentication offset is positive. When a real attack exists and the attack state corresponding to the real attack belongs to the set of feasible and business-damaging attack states, the minimum authentication offset is positive, ensuring that the statistical expectation of the robust log-likelihood ratio increment is greater than zero, thereby causing the sequential cumulative statistic to show a positive drift trend and eventually exceed the detection threshold.
[0035] Specifically, under no-attack conditions, the detection residuals follow a zero-mean Gaussian distribution; under attack conditions, the detection residuals follow a Gaussian distribution with a positive mean shift. Therefore, at the minimum shift... Under constraints, the following robust statistical model is established: ,in, Indicates time slot The observation and detection residuals This represents the variance of the detection residuals. This represents the worst-case attack assumption. Based on this, we construct the robust log-likelihood ratio increment: ; Based on the worst-case verification described above, the determination mechanism of this step can be further explained. For any condition satisfying... All of them are in an effective attack state. Therefore, under attack-free conditions, the mathematical expectation of the robust increment satisfies ; Under attack conditions, if the true mean shift is Then we have: ; Therefore, under normal conditions, the robust increment exhibits an overall negative drift; when a trailing interference satisfying the service impairment condition exists, the robust increment exhibits an overall positive drift. Thus, when the set of feasible and service impairment attack states is not empty, the minimum authentication offset is positive, thereby ensuring that the statistical expectation of the robust log-likelihood ratio increment is greater than zero. The sequential cumulative statistic shows a positive drift trend and ultimately exceeds the detection threshold with a high probability, achieving reliable alarm.
[0036] In one specific embodiment of this application, S4 includes: S41, Initialize the sequential cumulative statistic to zero; S42, in each time slot, add the sequential cumulative statistic of the previous time slot to the robust log-likelihood ratio increment of the current time slot to obtain the updated value; S43, compare the updated value with zero, and take the larger one as the sequential cumulative statistic for the current time slot.
[0037] Specifically, the minimum offset is certified based on the worst-case scenario. and robust log-likelihood ratio increment The base station accumulates the abnormal information reflected in the received residuals of each time slot on a time-slot basis to achieve online detection of tailing interference. Under no-attack conditions, the robust log-likelihood ratio increment generally exhibits a negative drift; however, when tailing interference exists that meets the service impairment conditions, the robust log-likelihood ratio increment generally exhibits a positive drift. Based on this difference, the sequential accumulation statistic is constructed as follows: ; Substituting the robust log-likelihood ratio increment into the above formula, we obtain the recursive form of the sequential statistic as follows: ; That is, first use the current time slot to observe the residual. Update historical statistics and then apply penalties. Suppressing spurious accumulations caused by noise fluctuations, and finally through The operation restricts the statistic to the non-negative interval, so that it falls back in time under normal conditions. However, under the condition of continuous injection of tailing interference, due to the long-term large receiving residual, the sequential statistic will show a stable rising characteristic.
[0038] In one specific embodiment of this application, S5 includes: S51, based on the system's preset average false alarm interval constraint, the detection threshold is calibrated using an exponential approximation relationship, so that the detection threshold is equal to the natural logarithm of the average false alarm interval; S52, compare the sequential cumulative statistics with the detection threshold. When the sequential cumulative statistics are greater than or equal to the detection threshold for the first time, determine that the control link has been subjected to tailing interference, trigger an alarm and output the detection stop time.
[0039] Specifically, in order to ensure that the system has a controllable false alarm level under normal operating conditions, the detection threshold is set. Pre-calibrate to meet the average false alarm interval constraint. ,in This represents the average false alarm interval under attack-free conditions. This represents the system's preset minimum average false alarm-free runtime. For the average false alarm interval constraint, an exponential approximation relationship is used for threshold calibration. .
[0040] Therefore, when the system requires a larger average false alarm interval, the corresponding detection threshold... As the threshold increases, the detector tends to become more conservative; when the system requires a faster alarm response, the corresponding detection threshold... The decrease in the sequential cumulative statistic improves detector sensitivity. This occurs when the sequential cumulative statistic first exceeds the detection threshold. When the control link is detected to be under tailing interference, an alarm is output. The corresponding detection stop time is defined as: .
[0041] This application does not make a judgment based on energy anomalies within a single time slot, but rather on whether the accumulated anomaly evidence from multiple time slots reaches a preset authentication threshold.
[0042] In one specific embodiment of this application, within the detection window after the attacker first satisfies the service impairment condition, the minimum value among the minimum authentication offsets of all time slots within the detection window is taken as the unified authentication offset, and the maximum value among the variances of the detection residuals of all time slots within the detection window is taken as the unified residual variance. A unified robust log-likelihood ratio increment is constructed based on the unified authentication offset and the unified residual variance.
[0043] Specifically, based on the aforementioned sequential cumulative judgment, to further illustrate the effective authentication capability of this application against service-damaging trailing interference, within the finite detection window after the attack first enters the service-damaging state, the subsequent length is defined as... The time slot set is in, This indicates the moment when the attacker first meets the service compromise condition. Within the detection window, a uniform, most unfavorable authentication parameter is further defined as follows: The above definition means that the most conservative unified detection model is constructed by taking the minimum authentication offset and the maximum residual variance within the detection window.
[0044] In one specific embodiment of this application, within the detection window, sequential accumulation is performed based on the unified robust log-likelihood ratio increment, and the detection probability of the obtained sequential cumulative statistic approaches one as the detection window length increases, wherein the detection probability is jointly determined by the standard normal cumulative distribution function, the unified authentication offset, the unified residual variance, the detection window length, and the detection threshold.
[0045] Specifically, under this worst-case model, the corresponding robustness increment can be written as: in Then its mathematical expectation is: ; This result demonstrates that even under the most adverse conditions, as long as the attacker enters the service-damaging area, the single-slot robust increment still has a positive mean, thus guaranteeing the sequential cumulative statistic. It continues to rise over time and eventually crosses the threshold. An alarm was triggered.
[0046] Since attackers cannot simultaneously satisfy all authentication dimensions, the feasibility of detection is fundamentally guaranteed, and the detection probability is low. With the length of the detection window The increase approaches Specifically, it satisfies: ; in, Represents the standard normal cumulative distribution function. , This represents the maximum residual variance within the window. This probability guarantee stems from the combined effect of worst-case authentication and sequential statistical accumulation: normal residuals fluctuate around the zero mean, while the persistent positive drift induced by trailing disturbances will push the statistic across the detection threshold with a high probability, thus ensuring that this type of attack is theoretically inherently detectable.
[0047] To verify the effectiveness of this application, a simulation experiment was conducted, as follows: I. Example Scenario Setup In the experimental scenario setup, refer to Figure 2 The base station (BS) is located at coordinates The initial position of the legally piloted drone is set to The initial position of the attack drone was set to and at a fixed flight altitude The following process involves tailing interference and control link interaction. The no-fly zone is set to... The radius of the circular region centered at the center ranges from 1 to 1. This describes the airspace avoidance constraints that both attackers and legitimate drones adhere to. The system carrier frequency is set to... Bandwidth set to The base station's transmission power is The noise power spectral density is The air-to-ground link path loss index from the base station to the drone is set to... The reference path loss is The attack path employs the Ricean fading model, with a path loss exponent of . The Rician factor is In addition, the maximum flight speed of the attack drone is set to... Predictive guidance gain set to The time slot length is set to The risk budget of the proposed STCSD detector is taken The authentication detection window length is set to The proposed method is used to evaluate its certification isolation distance and sequential detection performance under different tailing interference intensities, geometric positional relationships, and no-fly zone constraints.
[0048] II. Implementation Details 1) First, the impact of different attack feasible region modeling methods on detection performance was analyzed. By comparing the proposed STCSD method, the Partial Admissible Impact Screening Region (PA-ISR) method, and the Generalized Energy Detection (GED) method, the improvement effect of the constraint screening mechanism on the worst-case authentication results was evaluated. Thus, the differences among the three methods in worst-case signal offset authentication were compared.
[0049] 2) Secondly, the authentication detection performance under different interference intensities was tested by adjusting the jamming-to-signal ratio (JSR) from... Gradually improve to This study examines the worst-case authentication and isolation capabilities of three types of detectors under weak and strong interference conditions. Simulations were performed under different airspace restriction intensities, by varying the radius of the no-fly zone. The range of values was used to verify the effect of the detector on shrinking the attack feasible domain and the variation law of authentication detection performance under different no-fly zone constraints.
[0050] Figure 3 The results show that the proposed STCSD method achieves a larger worst-case signal offset margin on the feasible and business-damaging attack set after constraint filtering. STCSD exhibits better separation of worst-case authentication points compared to PA-ISR and GED. Its advantage stems from STCSD's simultaneous use of kinematic reachability constraints and no-fly zone evasion constraints to shrink the attacker's feasible domain, thereby eliminating physically unreachable attack states that would lead to overly pessimistic authentication results. In contrast, PA-ISR, due to its partial constraint filtering, and GED, due to its more relaxed influence domain modeling, exhibit smaller authentication biases.
[0051] Figure 4 This demonstrates when JSR from Increase to No-fly zone radius from Increase to At the same time, the proposed STCSD method always maintains the maximum authentication isolation distance. It also has a significant advantage under low interference-to-signal ratio conditions, such as in JSR. It can still be maintained This robustness is attributed to the joint mechanism of STCSD's map anchoring residual calibration and feasible region screening: the former suppresses background fluctuations caused by geometric changes, while the latter mitigates the excessive conservatism brought about by unreachable attack states. In contrast, PA-ISR and GED obtain significantly smaller authentication distances under the same parameter conditions, and exhibit more significant degradation in areas with weak interference.
[0052] It is worth noting that the terms "first" and "second" in this application are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0053] The above description, in conjunction with specific preferred embodiments, provides a further detailed explanation of this application and should not be construed as limiting the specific implementation of this application to these descriptions. For those skilled in the art, various simple deductions or substitutions can be made without departing from the concept of this application, and all such modifications or substitutions should be considered within the scope of protection of this application.
Claims
1. A method for detecting covert tailing interference attacks based on geometric consistency and constraint screening, characterized in that, include: S1, acquire the received signals of legal UAVs in each time slot, calculate the logarithmic power statistics of the time slot based on the received signals, and generate detection residuals by combining the map anchoring residuals; S2, from the pre-built set of attack states, select a set of feasible and business-damaging attack states that meet the physical feasibility conditions and the business damage conditions, and determine the minimum authentication offset on the set of feasible and business-damaging attack states. S3, construct the robust log-likelihood ratio increment for each time slot based on the detection residual and the authentication minimum offset; S4, based on the robust log-likelihood ratio increment, perform sequential accumulation to obtain the sequential accumulation statistic; S5, compare the sequential cumulative statistics with a preset detection threshold, and determine that the control link is subjected to tailing interference when the sequential cumulative statistics exceed the detection threshold.
2. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, S1 includes: S11, obtain the position vector of the base station and the position vector of the legal UAV in each time slot, and calculate the geometric distance between them; S12, Calculate the benign reference receiver log power based on the coverage map or large-scale path loss model and the geometric distance; S13: Collect multiple complex baseband snapshots within the received signals of legal UAVs in each time slot, and calculate the logarithmic power statistics of the time slot; S14, subtract the benign reference reception logarithmic power from the time slot logarithmic power statistic to obtain the detection residual.
3. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, S2 include: S21. Based on the kinematic reachability constraints and no-fly zone avoidance constraints of the attack drone, determine the reachable location area of the attack drone in each time slot, and construct an attack state set in combination with the transmission power range; wherein, the attack state set includes the position of the attack drone, transmission power, kinematic reachability constraints, no-fly zone constraints, and service damage conditions; S22, Select physically feasible attack states that satisfy kinematic reachability constraints and no-fly zone avoidance constraints from the set of attack states; S23, filter out the service-damaging attack states that satisfy the interference-to-noise ratio threshold from the physically feasible attack states to obtain a set of feasible and service-damaging attack states. S24, on the set of feasible and business-damaging attack states, calculate the mean offset introduced by each attack state on the detection residual, and take the minimum value of the mean offset as the minimum authentication offset.
4. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, S3 includes: Based on the detection residual, the minimum authentication offset, and the variance of the detection residual, construct the robust log-likelihood ratio increment for each time slot; the robust log-likelihood ratio increment is the minimum authentication offset divided by the variance of the detection residual multiplied by the detection residual, and then subtracted by the square of the minimum authentication offset divided by twice the variance of the detection residual.
5. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, S4 include: S41, Initialize the sequential cumulative statistic to zero; S42, in each time slot, add the sequential cumulative statistic of the previous time slot to the robust log-likelihood ratio increment of the current time slot to obtain the updated value; S43, compare the updated value with zero, and take the larger one as the sequential cumulative statistic for the current time slot.
6. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, S5 include: S51, based on the system's preset average false alarm interval constraint, the detection threshold is calibrated using an exponential approximation relationship, so that the detection threshold is equal to the natural logarithm of the average false alarm interval; S52, compare the sequential cumulative statistics with the detection threshold. When the sequential cumulative statistics are greater than or equal to the detection threshold for the first time, determine that the control link has been subjected to tailing interference, trigger an alarm and output the detection stop time.
7. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, Within the detection window after the attacker first satisfies the service impairment condition, the minimum value among the minimum authentication offsets of all time slots within the detection window is taken as the unified authentication offset, and the maximum value among the variances of the detection residuals of all time slots within the detection window is taken as the unified residual variance. A unified robust log-likelihood ratio increment is constructed based on the unified authentication offset and the unified residual variance.
8. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 7, characterized in that, Within the detection window, sequential accumulation is performed based on the unified robust log-likelihood ratio increment. The detection probability of the resulting sequential cumulative statistic approaches one as the detection window length increases. The detection probability is determined by the standard normal cumulative distribution function, the unified authentication offset, the unified residual variance, the detection window length, and the detection threshold.
9. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, The detection residual follows a zero-mean Gaussian distribution when there is no attack; when there is a real attack and the attack state corresponding to the real attack belongs to the set of feasible and business-damaging attack states, the detection residual follows a Gaussian distribution with a mean not less than the minimum authentication offset.
10. The method for detecting covert tailing interference attacks based on geometric consistency and constraint screening according to claim 1, characterized in that, When the set of feasible and business-damaging attack states is not empty, the minimum authentication offset is positive. When a real attack exists and the attack state corresponding to the real attack belongs to the set of feasible and business-damaging attack states, the minimum authentication offset is positive, ensuring that the statistical expectation of the robust log-likelihood ratio increment is greater than zero, thereby causing the sequential cumulative statistic to show a positive drift trend and eventually exceed the detection threshold.